CVE-2026-33001

Published Mar 18, 2026

Last updated a month ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-33001 is a path traversal vulnerability affecting Jenkins versions 2.554 and earlier, as well as Jenkins LTS 2.541.2 and earlier. This flaw stems from Jenkins' inadequate handling of symbolic links during the extraction of `.tar` and `.tar.gz` archives. Attackers can exploit this by crafting malicious archives containing symbolic links that direct file writes to unintended locations on the filesystem. The vulnerability allows for arbitrary file writes, limited only by the file system permissions of the user running Jenkins. Exploitation requires an attacker to have "Item/Configure" permission or the ability to control agent processes. This can be leveraged to deploy malicious scripts or plugins onto the Jenkins controller, potentially leading to further compromise.

Description
Jenkins 2.554 and earlier, LTS 2.541.2 and earlier does not safely handle symbolic links during the extraction of .tar and .tar.gz archives, allowing crafted archives to write files to arbitrary locations on the filesystem, restricted only by file system access permissions of the user running Jenkins. This can be exploited to deploy malicious scripts or plugins on the controller by attackers with Item/Configure permission, or able to control agent processes.
Source
jenkinsci-cert@googlegroups.com
NVD status
Modified
Products
jenkins

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-59
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-22

Social media

Hype score
Not currently trending

Configurations